Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Device Certification and Recertification
Governance, Ownership & Risk

Device Certification and Recertification

← Back to Glossary
By NHI Mgmt Group Updated September 26, 2026 Domain: Governance, Ownership & Risk

Device certification and recertification are governance processes that confirm whether a device should be allowed to operate and remain trusted over time. They help healthcare organisations assess patching status, security configuration, manufacturer risk, and ongoing suitability for clinical use.

What Device Certification and Recertification Covers

Device certification and recertification sit at the governance layer of device trust. The process asks whether a device is fit to operate now, and whether the reasons it was approved remain valid as its patch level, configuration, exposure, and operational role change.

That makes the term broader than a one-time approval. Certification establishes the initial trust decision, while recertification is the periodic or event-driven recheck that keeps the decision aligned with current security posture and business need.

Why It Matters in Healthcare Environments

In healthcare, device trust is tightly linked to patient safety and operational continuity. Clinical devices often remain in service for long periods, connect to sensitive systems, and depend on manufacturer support, firmware, and hardening that can drift over time.

Recertification is what prevents an originally acceptable device from becoming an accepted risk. A device may still function clinically while no longer meeting patching expectations, network segmentation rules, or vendor support assumptions, so governance has to track suitability continuously rather than relying on first approval alone.

For teams building review programs, the underlying logic is similar to access certification: trust is renewed only when the current state still supports the original decision. NHIMG’s Access Reviews and Certification Guide is a useful parallel for understanding how review cycles should close the loop rather than become rubber-stamp exercises.

What Gets Evaluated During Certification

A meaningful certification review usually looks at the device’s patching status, configuration baseline, manufacturer advisories, network exposure, and ownership. Those factors help determine whether the device is hardened enough for its intended use and whether compensating controls are needed.

Lifecycle questions matter too. Devices can be newly deployed, moved to a different clinical area, repurposed, or left in place after vendor support has ended. Each of those changes can alter the trust decision even when the device itself has not visibly failed.

That is why lifecycle governance, inventory accuracy, and recertification are inseparable. NHIMG’s NHI Lifecycle Management Guide and Joiner-Mover-Leaver (JML) Guide both illustrate the same operational pattern, namely that trust decisions weaken quickly when asset state and ownership are not actively maintained.

Governance Outcomes and Control Alignment

Device certification and recertification translate trust into an auditable governance decision. The outcome is not simply “allow” or “deny”; it is a documented statement about why a device can operate, what conditions must remain true, and when the decision must be revisited.

In practice, that means the process should align with inventory, change management, vulnerability handling, and exception management. If a device falls out of policy, the organisation needs a clear path to remediate, contain, or formally accept the residual risk until the next review.

For broader governance structure, IAM and IGA Basics helps frame how governance programs track what is approved, who owns it, and when approval must be revalidated. The same discipline is what keeps device certification from becoming a one-time checkbox.

Risk and Threat Considerations

Devices that are certified once and then left unchecked can accumulate patch gaps, configuration drift, unsupported software, and hidden exposure. In connected healthcare environments, that creates an easy path for misuse, persistence, or lateral movement through a trusted asset.

Failure mechanism: The device remains operational while its security posture degrades, so the original trust decision no longer matches reality and weak controls are treated as still acceptable.

Impact: Exposure can include malware footholds, compromised clinical data, disrupted workflows, and unsafe dependence on equipment that should have been revalidated or removed from service.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-1 — Inventory and Control of Enterprise AssetsDevice certification depends on knowing which devices exist and their current state.
CIS-4 — Secure Configuration of Enterprise Assets and SoftwareRecertification evaluates whether device configurations still meet secure baseline requirements.
Recommendation — Maintain authoritative device inventories so certification reviews target the right assets. Enforce secure configuration baselines and verify them during recertification cycles.
NIST SP 800-53 Rev 5CM-8 — System Component InventoryCertification and recertification rely on accurate component inventory and ownership tracking.
CM-2 — Baseline ConfigurationThe term is materially tied to whether device baselines remain acceptable over time.
CA-7 — Continuous MonitoringRecertification is a monitoring-driven trust reassessment rather than a one-time event.
Recommendation — Keep an accurate component inventory so device approval decisions can be revisited reliably. Define and maintain approved baselines for devices before recertifying them. Use continuous monitoring data to trigger device recertification when posture changes.

Practitioner Guidance

Governance implication: Treat certification as a living approval, not a one-time sign-off. The review should have an owner, a clear trigger for recertification, and a documented basis for any exception so that trust can be challenged when the device, environment, or support status changes.

What to watch for: Long review intervals, stale inventories, unsupported firmware, and repeated exception renewals are strong signs that the process is drifting from governance into formality. Those are the cases most likely to hide real exposure.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org